Item logo image for SecretSifter: Live Credentials & Secrets Scanner

SecretSifter: Live Credentials & Secrets Scanner

5.0(

2 ratings

)
ExtensionDeveloper Tools44 users
Item media 3 (screenshot) for SecretSifter: Live Credentials & Secrets Scanner
Item media 1 (screenshot) for SecretSifter: Live Credentials & Secrets Scanner
Item media 2 (screenshot) for SecretSifter: Live Credentials & Secrets Scanner
Item media 3 (screenshot) for SecretSifter: Live Credentials & Secrets Scanner
Item media 1 (screenshot) for SecretSifter: Live Credentials & Secrets Scanner
Item media 1 (screenshot) for SecretSifter: Live Credentials & Secrets Scanner
Item media 2 (screenshot) for SecretSifter: Live Credentials & Secrets Scanner
Item media 3 (screenshot) for SecretSifter: Live Credentials & Secrets Scanner

Overview

Detects secrets, API keys, and tokens in JS, JSON, XML, and HTML at runtime

SecretSifter is a runtime secrets scanner built for penetration testers, bug bounty hunters, and security engineers. It automatically intercepts and scans network traffic in the active tab — JavaScript files, JSON API responses, XML responses, HTML pages, and WebSocket frames — and flags exposed secrets such as: • API keys, Bearer tokens and JWT secrets • Passwords and credentials in response bodies KEY FEATURES • T1 / T2 / T3 confidence tiers to separate real findings from noise • WebSocket scanning — intercepts both incoming and outgoing WS frames • CDN blocklist — skip known third-party libraries and analytics scripts automatically • Suppressed key names — silence app-specific noise with one click • Full findings report with severity badges (Critical / High / Medium / Low) • Export findings to JSON, CSV, or HTML report • Export scanned URL list (JS, JSON, HTML, XML, requests, WebSocket) • DevTools panel + popup — works however you prefer • Privacy-first — all findings stored locally in your browser; the only external call is an optional Google Maps API key validation probe sent directly to Google DESIGNED FOR SECURITY PROFESSIONALS Scanning is opt-in per tab. No accounts, no telemetry, no developer-controlled servers.

Details

  • Version
    1.1.0
  • Updated
    March 26, 2026
  • Offered by
    gorijala2k16
  • Size
    76.21KiB
  • Languages
    English (United States)
  • Developer
    Email
    gorijala2k16@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

SecretSifter: Live Credentials & Secrets Scanner has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

SecretSifter: Live Credentials & Secrets Scanner handles the following:

Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps